Threat Intelligence
Map your findings to MITRE ATT&CK techniques, track CISA KEV listings, monitor breach databases for your domains. Connects external threat data to your specific Sectora findings.
Three intel sources, one view
- MITRE ATT&CK — every Sectora finding maps to one or more ATT&CK techniques. Filter your queue by technique (e.g. "show me all T1190 Exploit-Public-Facing-Application findings").
- CISA KEV catalog — Known Exploited Vulnerabilities. Polled hourly. Any matching CVE in your SCA findings instantly gets re-prioritised to Critical.
- Breach corpus monitoring — your domains + email patterns + employee emails (BYO list) are checked against the latest breach dumps. Match = leaked-credential signal with high confidence.
ATT&CK mapping in practice
For each finding, the Threat Intel panel shows the mapped techniques + sub-techniques + a kill-chain visualization (where in the attack flow this sits). Useful when you're reporting risk to a security-mature board — they want techniques, not CVE IDs.
Trending techniques
The Trending dashboard shows ATT&CK techniques that have spiked across Sectora's customer base in the last 7/30/90 days — useful early warning. If T1190 spikes industry-wide, your public-facing apps just became higher-risk regardless of your specific findings.
KEV integration
CISA's KEV catalog is the authoritative list of CVEs with confirmed in-the-wild exploitation. Sectora polls hourly; any new addition that matches a finding in your SCA gets:
- Severity re-rated to Critical (regardless of CVSS)
- Risk score multiplier 1.5×
- Alert fired immediately to your KEV-routing channel
- Virtual-patch suggestion if Shield is enabled + a known mitigation pattern exists
Breach corpus monitoring
Sectora maintains an indexed view of public breach dumps (haveibeenpwned API + our own corpus). Your monitored domains + employee email patterns are checked daily; matches surface as Critical leaked-credential findings.
Set up at Settings → Threat Intel → Domains + Email patterns. The check uses k-anonymized hashing — your emails never leave your tenant in plaintext; only SHA-256 prefixes are sent to the corpus API.
Integrating with your SOC
For mature security teams running a SIEM, Sectora can stream the Threat Intel feed:
- JSON over webhook — finding + mapped techniques + KEV context in real time
- Splunk HEC ingest
- STIX 2.1 feed (subscribe via Settings → Threat Intel → STIX endpoint)
What's next
- Risk Scoring — how Threat Intel feeds into prioritisation.
- CVE Detection — targeted scanning for specific CVEs.